Greenbone OS: Release History
Please read in our Learning Center about how to execute a upgrade and what to consider for this: GSM: Upgrade
Continuously new and improved features are made available via upgrades.
Maintained via patch level updates:
2011-12-12: Greenbone OS 1.7.0 (END-OF-LIVE: 2013-06-30)
An overview on old releases that are not supported anymore is available here: Greenbone OS: Old Releases.
2013-02-12: Greenbone OS 2.1.0
Latest patch level: 2.1.0-20 (2013-05-16)
The items marked with (*) will change the default behaviour.
-
Auto-FP: Automatic assistant for detecting likely False Positives
The design of the Greenbone technology includes minimum tolerance for False Negatives, because a False Negative means missing a message for a real threat. Instead, when in doubt, False Positives are tolerated. This means messages may be present where there is actually no problem. The reason for this strategy is pretty simple: False Positives are manageable, False Negatives are not.
Greenbone provides unique functions for False Positive management. For quite some time already the Overrides feature has allowed easy flagging of False Positives, including tolerance duration and generalization of the override.
The Auto-FP feature is the next consequent step: it is internal intelligence that identifies, marks and filters likely False Positives by information intersection. This way the user has a helpful yet simple instrument for the assessment of security messages. Toggling some switches quickly changes the view. This method is especially helpful for systems where patch level versioning of services and applications is not visible.
The Auto-FP feature uses information from the target systems as well as expert knowledge that is extended and updated via the Greenbone Security Feed.
-
Tasks: Multiple Alerts
Tasks can now be coupled with a arbitrary number of different Alerts. This allows for example to send different types of reports to different email addresses and at the same time open a ticket in your issue tracking system and finally feed the ISMS and the IPS system - all automatically each time the scan task finishes.
-
Overview on closed CVE's.
In reports the user can get a list of all CVE's that are officially closed by vendor updates on the respective system.
-
Notes: Now with new object management
Notes are now handled via the new object management and therefore gain access to the power filter and to the trashcan. Functionalities Clone and Export are also added.
Furthermore Notes can now be directly created even without necessity to go via a Task.
All user interfaces where lists of Notes were shown, like for NVT Details, were changed so that the lists are replaced by a link into the Notes management with a appropriate context Filter.
-
New object class "Filter".
The new object class allows to store rules for search and sorting. These can be applied for Targets, Reports and other objects and later easily be used.
For example, a report filter can be configured in the report view and later be used as attribute of a Alert.
The Filters also got the new object management interface which offers an easy way to manage them.
-
SecInfo Management: Becomes a menu of its own in web interface
The relevance of the SecInfo Management increases and becomes a main menu next to Task Management and Asset Management.
Directly after an upgrade to this GOS version the SecInfo Management is unavailable for up to 24 hours, including the depending prognosis functionality. The reason is that the database is rebuild during the extension of the data.
-
SecInfo Management: CPE data with new object management
The CPE Lookup is replaced by the new object management. This makes interactive search, the Powerfilter and many other functions available for CPE data. The Greenbone SecInfo CPE database contains not only the official CPE database of MITRE. It also contains all CPEs used in any of the CVEs. In total this database contains ca. 150,000 CPEs.
-
Wizard Framework
The new Wizard Framework is a technical basis for embedding wizards. These wizards are usually short-cuts where as many things as possible are done automatically applying sensible defaults.
Wizards appear as long as the user did not work a lot with the application. After a certain number of objects are managed (this number is configurable by the user) the wizard does not appear anymore, but can be called via the wizard icon.
-
Quick start Task Wizard: Immediately scan an IP address
With the Task Wizard you only need to enter a target system address. The wizard will do all necessary configurations and start the scan task.
-
(*) LDAP/ADS Authentication: Is now done consistently via "LDAP per-user". The handling of authorization (for example roles) is not managed anymore via LDAP/ADS. The configuration of a LDAP or ADS in GSM needs to be done anew.
-
Tasks/Asset Management: A new switch for Tasks allows to determine whether the scan of this task are to be considered for the Asset Management.
-
Schedules: Daylight saving is now automatically considered.
-
Schedules: Can now be modified via the new edit functionality.
-
Targets: Extended powerfilter now covers sorting. The entry field of the powerfilter can now process any filter control element.
-
Alerts: The new attribute "Filter" allows to apply individual report filter rules for those alerts where a scan report is processed.
-
New Alert for automatic data transfer to ISMS verinice.PRO.
-
Airgap Synchronization: GSM from GSM 500 upward offers a Feed synchronization via USB sticks between devices of the same type. The instructions when to plug or change the USB stick are managed via the LCD display. It is not necessary to log into the system and even a daily update means only little effort.
-
Full availability of web interface even concurrently with comprehensive feed updates.
-
Scanner is extended with comprehensive certificate engine to allow various types of x509 (ssl) certificate checks such as validity, wrong use etc.
-
Upgrade Nmap: The integrated network mapping tool is updated to version 6.01.
-
Upgrade w3af: The integrated web application scanner w3af is updated to version 1.1.
-
Proxy for Feed synchronization: Now also proxies with authentication can be used.
-
Changed sequence and grouping of menu items of web interface.
Patch level GOS 2.1.0:
2.1.0-20 (2013-05-16): Feed update routine now applies maximum compression. Transfer duration as well as transfer volume are lowered significantly. (#29223).
Bugfix to not truncate notes when attached to HTML reports as used in email alerts (#27196, #2013020810000019).
Extended GXR report to show also name and comment of the respective task (#28811, #2013040210000026).
Extended verinice alert to use "digest" for HTTP and "anyauth" for HTTPS for authentication (#29257).
Bugfix for verinice Source-IDs in verinice alert (#29193, #2013041810000051).
Web interface: Missing session tokens or missing parameters will now lead automatically to login page or to a sensible page. This makes using bookmarks smoother. And it allows to create URLs (possibly in other applications) that will directly and smoothly guide users (like links to NVT or CVE details) (#29288, #29289).
Fixed bug to show always correct Operating System Icon for Greenbone appliances (#28617).
Bugfix for GSM 25V to allow configuration of eth0 via gos-admin-menu (#28725).
2.1.0-19 (2013-05-07): Certificate validity extension for internal services. Without this validity extension no scanning will be possible anymore. The expiry of the certificate depends on GSM type and production date. An upgrade is highly recommended in any case for all GSMs. (#29475).
2.1.0-18 (2013-03-22): Bugfix for power filter to keep the character "+" in search terms (#28357, #2013031210000018).
Bugfix for power filter to handle character "#" properly in search terms (#28359).
Made setting for management interface ("ifadm" in cli-admin) available in gos-admin-menu in submenu Network/ETH (#28385).
Further reduced acccess rights of internal administration account (admin) (#28499).
Bugfix to prevent editing of a target-in-use under certain conditions by greying out edit icon (#28529).
Bugfix for internal process management to avoid running but unused OMP service processes. This happened under rare conditions only and had no security impact. (#28530).
Additional internal sanity check for release change (#28531).
Bugfix for misleading example for sync times in gos-admin-menu (#28337, #2013031110000011).
Bugfix to remove unneeded files from internal cache after a release change like from 2.0 to 2.1. This saves some disk space (#28579).
2.1.0-17 (2013-03-08): New: Configuration for authenticated proxies for feed synchronisation now also possible via GOS-Admin-Menu under Feed->Credentials (#27113).
Bugfix for partition backup and snapshot for GSM from model 500. Requests for Backup or Snapshot via CLI-Admin were not executed properly. However, the backup managment via boot menu was not affected (#28273).
Improvement for results in prognostic reports in the web client: No fixed-with line-breaks anymore (#27946).
Bugfix for Trashcan: Notes will now also removed if the Trashcan is emtpied (#27998).
2.1.0-16 (2013-02-27): Bugfix for Problem with concurrently executed scans and feed-updates (#28143, #2013021910000025, #2013022510000022).
Bugfix for "Show Notes" and "Only show hosts that have results" of Report Filters that did not change upon "Apply" (#27945, #2013021510000014).
2.1.0-15 (2013-02-20): Users with role Observer will not get offered the quick scan wizard by default anymore (#27806).
In scan result browser, dark blue forward and back buttons on gray headlines are replaced by forward/backward icons (#27933).
Update of internal on-board omp client command line tool (#27862).
2.1.0-14 (2013-02-19): Scan sensors are now automatically updated with new releases via Master. Also, a system upgrade on the master will automatically run a system upgrade on its sensors. The GOS administation menu offers configuration of the list of connected and therefore managed sensors (#26010).
2.1.0-13 (2013-02-12): Last release of Beta phase. First release of 2.1.0.
2012-04-30: Greenbone OS 2.0.0
Latest patch level: 2.0.0-32 (2013-05-07)
The items marked with (*) will change the default behaviour.
-
(*) New configuration object: Port Lists.
Port Lists offer transparent view and editing of ports to be scanned. Port Lists are associated with a target. Especially it is now easily possible to create arbitrary combinations of TCP and UDP Ports for a single Target.
The traditional port selection "default" becomes "OpenVAS Default". It is accompanied with a selection of pre-defined Port Lists that refer to best practice of NMap or to IANA.
Port scans for UDP are now always executed in case UDP ports are specified. Before there were some special port scanner switches to explicitly allow or deny UDP port scans. These switches are removed now. Therefore check your Tasks whether these use UDP ports that in fact you do not want to be scanned.
-
(*) The CVE and BID references are no longer part of the result text of a NVT. They are not part of a new section "References". This applies for the web interface and also for various report format plugins.
This means that scans with this new version will show changes compared to scans with previous versions: The last few lines of each results with the references will be missing.
-
Expert mode for network integration allows VLAN with 64 up to 256 per Ethernet port.
-
New default Report Format: Greenbone Executive Report (GXR). It produces a PDF with various graphical summaries (pie-chart, block-chart, topology map, top 10 lists).
-
Targets: It is now possible to upload a text file with a list of target systems of up to 4000 IPs.
-
Targets: When entering a target manually or uploading target lists, identical entries will be eliminated.
-
Tasks: Users that are added as observer can now also add notes and overrides.
-
LDAP authentication: Now configurable per-user and via simple LDAP connection.
-
Results view: New info boxes with references and with product detections.
-
Targets: Upload of targets via text file now possible.
-
Targets: Complete new user interface with paging, power filter, cloning, import, export, upload of targets via text file, separation of creation and view, info about creation and modification times as well as object IDs.
-
Feed-Sync: Can now explicitly be switched off.
-
Accelerated boot process.
-
My Settings: New setting "Rows Per Page" pre-defines number of rows for object lists in the user interface. This applies currently only for Targets, but will be extended to other objects in the future.
Patch level GOS 2.0.0:
2.0.0-32 (2013-05-07): Certificate validity extension for internal services. Without this validity extension no scanning will be possible anymore. The expiry of the certificate depends on GSM type and production date. An upgrade is highly recommended in any case for all GSMs. (#29475).
2.0.0-31 (2013-03-22): Bugfix to remove unneeded files from internal cache during release change from 2.0 to 2.1. This saves some disk space (#28576).
2.0.0-30 (2013-03-21): Bugfix for misleading example for sync times in gos-admin-menu (#28337, #2013031110000011).
Bugfix for internal process management to avoid running but unused OMP service processes. This happened under rare conditions only and had no security impact. (#28530).
Further reduced acccess rights of internal administration account (admin) (#28499).
2.0.0-29 (2013-03-07): Bugfix for partition backup and snapshot for GSM from model 500. Requests for Backup or Snapshot via CLI-Admin were not executed properly. However, the backup managment via boot menu was not affected (#28273).
Dropped some unnecessary sync-calls to the feed server (#27410).
Bugfix for improved timestamps for notes in PDF reports (#26757).
Bugfix for improved timestamps for GXR and HTML reports (#27066).
Bugfix for NTP-Check in GOS-Admin-Menu (#27420).
2.0.0-28 (2013-01-17): Bugfix for FTP Login/Passwort data. These are now again accepted, also via a import (#26683).
Bugfix for Master-Slave communication when using Credentials (#26424).2.0.0-27 (2012-12-08): Bugfix for token-loss (requiring to log in again) in the web interface that occasionally occurred for some browsers in different, non-reproducible ways. The bug was therefore called "the Yeti" (#23571, #23169, #23983, #26232, #26090).
2.0.0-26 (2012-11-14): Bugfix for Feed synchronization Master-GSM to GSM 25 (#25732).
Bugfix (yet another) for w3af execution (#25905).
2.0.0-25 (2012-11-09): Security-Bugfix for Sourcefire Alert. A registered user was able to execute shell injections with special crafted parameters (#25952, CVE-2012-5520).
Bugfix for performance request of slaves regarding duration (#21541, #25165).
Bugfix for w3af execution (#25905).
2.0.0-24 (2012-10-25): Improvement of CVE details dialog of the web interface to have the list of CPEs ordered alphabetically (#23168).
Bugfix for CVE details dialog of the web interface so that no error occurs anymore when associated NVT names contain special characters. (#25439).
Bugfix for network interface configuration of GSM 550 (#25439).
Ike-scan is not part of GOS and therefore the corresponding NVT was removed from GOS (#25458).
Bugfix for NTP configuration on GSM 25 and GSM 100 (#25601).
Bugfix for GSM 25 that removed a error message about SSL (#25160).
Selfcheck of gos-admin-menu extended with check for DNS configuration (#25627).
Bugfix for SCAP data synchronisation for special cases where database was emptied (#25162).
2.0.0-23 (2012-09-22): Bugfix for SCAP data synchronisation which improves prognosis scans (#24689).
Bugfix for creation of port lists to consider also the first entry of a new entry and to properly bind port lists with targets during userdata import (#24724).
2.0.0-22 (2012-09-13): Bugfix for GSM 510 for the Slave-Sync functionality (#23814).
Bugfix für GSM 100 for Web-Interface availability (#24351).
Bugfix for Alert for Sourcefire Defense Center (#24249).
2.0.0-21 (2012-08-25): Bugfix for validation of hostnames with dashes (#23689).
Extension of GOS Admin Menu with Backup and Recovery for user data (#22463).
Bugfix for import of hostnames to skip whitespaces (#23812).
Bugfix for schedules to allow duration limitation also for single runs (#23812).
2.0.0-20 (2012-08-23): Security-Bugfix for OMP command "get_reports". A registered user was able to retrieve data of scan reports of other users registered on the same GSM, provided OMP is activated (#23167).
Security Bugfix for search patterns. A registered user was able to provoke a Internal Error with special search patterns so that no report is created and the web interface receives no response from the database (#23206).
Security Bugfix for integrated help system. A registered user was able to end session for all current users by crafting a special URL into the integrated help system. (#23207).
Bugfix for Webtimeout setting in GOS Admin (#22458).
Bugfixes for GXR built-in Report Format Plugin (update to version 1.0.2) (#22401 and #22555).
New GOS Admin Menu command to show the SSH fingerprint (#22686).
Bugfix for deactivation of ITG Report Format Plugin (#22520).
Performance improvement by reduction of program calls during scan process (#22713).
Bugfix for temperature graphs: The degree symbol is now visible (#22339).
Bugfix for temperature graphs on GSM 510: Wrong sensor data are removed. (#22751).
Performance improvement by reduction of MD5 computations (#22900).
Bugfix for Keyboard-Layout switch of GSM 500 (#22906).
Extension for XML-Export of reports: The comment of a task is now also included (#22963).
Extension for XML export and XML import of reports: Host details are now exported as well as imported (#22277).
Reduced size of user data backup by dropping rebuildable data (#22983).
Bugfix (don't overwrite CA data) and improvement (reduced size) for user-data restore (#22984).
Improved support for USB sticks for backups (#23004 and #23005).
Improved answer times of web interface when large reports are prepared (#23008).
Bugfix for credentials that were configured with certain SSH keys (#22708).
Bugfix for Master-Slave mode: Scan intensity settings where not transferred correctly to the slave. The slaved used always the defaults settings (#23202).
Consolidated SSL cipher offers for web interfaces (#18749).
Bugfix for Scan Configuration editor: Multiple existing names do not block editing anymore (#23687).
2.0.0-19 (2012-06-28): Bugfix for Umlauts and other special characters in reports. Bugfix for file upload for NVT preferences (#22092). Wrong message for SSH at boot time fixed (#21816). Start for GSM 500 and GSM 510.
2.0.0-18 (2012-06-20): Internal improvement for DNS.
2.0.0-17 (2012-06-19): Bug fix for Target editor when Target Locators are used. Bug fix for Target editor to improve hostname acceptance. Bug fix for Trashcan to delete certain objects ultimately. Bug fix to better import certain reports. Removed misleading warning at boot time. Improved layout of GXR PDF Report Format. Bug fix for Task editor availability. Consistent time stamp formats in PDF Report Format.
2.0.0-16 (2012-05-04): Extended gos-admin-menu with complete scan user management for GSM 25 as well as fixed feed age. Streamlining for GSM 25. Start for GSM 100.
2.0.0-15 (2012-30-04): First customer release of 2.0.0. Start for GSM 25.
2011-12-12: Greenbone OS 1.7.0
Latest patch level: 1.7.0-28 (2012-11-09)
Important note: Even when the upgrade status shows the upgrade is finished, a background process still runs an update for up to 2 hours.
During this time neither a reboot nor a scan should be executed.
Note: The prognosis function is available about one day after the upgrade.
The items marked with (*) will change the default behaviour.
-
New Feature: The new Asset Management offers an overview on all scanned systems independently of the actual scan tasks.
-
New Feature: Current CVE and CPE data are distributed via the Greenbone feed service. These are available in the user interface as direct cross links wherever CVEs or CPEs are referenced.
-
New Feature: The new SecInfo Management offer direct access to details of CVEs, CPEs and NVTs.
-
New Feature: Prognostic scans allow an upfront analysis about potential vulnerabilities of hosts. This happens without accessing these systems via the network and therefore the scan duration is virtually zero.
-
New Feature: Users can grant read access to other users for their tasks. For any task it is possible to name one or many observers. The task will then appear in the task overview of the observer users.
-
New Feature: Users can configure their time zone. Any times visible in the web interface will be adapted accordingly for them.
-
(*) XML Report Format and OMP: For any timestamp ISO 8601 format is now applied including timezone information.
Please pay attention about the following aspects of this change:
-
In case you are using Greenbone Security Desktop you have to update to Version 1.2.1 or higher. From this version on, the ISO timestamps are handled properly.
-
In case you have exported XML reports with GOS prior 1.7, timestamps are implicitly in UTC timezone. Importing such a report with GOS 1.7 or higher will apply the timezone of the user if no timezone is explicitly provided in the report. So, in case users need to adjust the timezone for a imported report, they can temporarily configure their own timezone to the one that corresponds to the report in order to execute the import. Old non-ISO timestamps are of course properly handled in general and the maximum timeshift that could happen is the distance between the timezones.
A XML report created with GOS 1.7 or newer can not be imported with a GOS release prior 1.7.
-
In case you have established an individual processing chain via OMP, you should adapt the processing to the new ISO 8601 timestamps. This is not mandatory if the timestamps are only processed as character strings.
-
In case you are using imported Report Format Plugins you have to remove them and import the respective updates for GOS 1.7. New versions of our plugins can be found on our Report Format Plugins overview.
-
-
(*) PDF/HTML/Text Reports: Will now contain, if available, the hostname additionally to the IP address. No special Scan-Configurations are necessary for this anymore.
-
(*) OMP 3.0: The version identification of the OMP protocol increases for GOS 1.7 due to the timestamp changes described above from 2.0 to 3.0.
In case you have individual processing chains based on OMP, you might have to consider the change in the version identification on the one hand and the new timestamp format ISO 8601 on the other hand.
-
Overrides: It is now possible to set a validity duration for a override. After tolerated validity, the overrides are automatically deactivated.
-
Notes: It is now possible to set a validity duration for a note. After tolerated validity, the notes are automatically deactivated.
-
GOS Admin: The CLI Admin interface for the base configuration of Greenbone OS is extended with a first version of comfortable dialog-driven menus.
-
Web-GUI: The navigation transforms from the left-hand side box into a horizontal menu.
Patch level:
1.7.0-28 (2012-11-09):
Security-Bugfix for Sourcefire Alert. A registered user was able to execute shell injections with special crafted parameters (#25952).
1.7.0-27 (2012-10-23):
Bugfix for SCAP data synchronisation which improves prognosis scans (#24689).
Bugfix for userdata backup to prevent inactive special-named users after a restore (#25571).
Selfcheck of gos-admin-menu extended with check for DNS configuration (#25627).
1.7.0-26 (2012-08-30):
Bugfix for Scan Configuration editor: Multiple existing names do not block editing anymore (#23687).
Bugfix for validation of hostnames with dashes (#23689).
1.7.0-25 (2012-08-21):
Security Bugfix for search patterns. A registered user was able to provoke a Internal Error with special search patterns so that no report is created and the web interface receices no response from the database (#23206).
Security Bugfix for integrated help system. A registered user was able to end session for all current users by crafting a special URL into the integrated help system. (#23207).
Bugfix for Master-Slave mode: Scan intensity settings where not transferred correctly to the slave. The slaved used always the defaults settings (#23202).
1.7.0-24 (2012-08-04):
Extension for XML export and XML import of reports: Host details are now exported as well as imported (#22277).
1.7.0-23 (2012-08-02):
Security-Bugfix for OMP command "get_reports". A registered user was able to retrieve data of scan reports of other users registered on the same GSM, provided OMP is activated (#23167).
Bugfix for Webtimeout setting in GOS Admin (#22458).
Bugfix for deactivation of ITG Report Format Plugin (#22520).
Performance improvement by reduction of program calls during scan process (#22713).
Bugfix for temperature graphs: The degree symbol is now visible (#22339).
Performance improvement by reduction of MD5 computations (#22900).
Extension for XML-Export of reports: The comment of a task is now also included (#22963).
Reduced size of user data backup by dropping rebuildable data (#22983).
Improved answer times of web interface when large reports are prepared (#23008).
Extension of GOS Admin Menu with "Flash Upgrade" (#22464).
Extension of GOS Admin Menu with "Backup" for user data backup (#22463).
Bugfix for credentials that were configured with certain SSH keys (#22708).
1.7.0-22 (2012-07-03):
Bug fix to better import certain reports (#21502).
Bug fix for Trashcan to delete certain objects ultimately (#21539).
Bug fix for Target editor to improve hostname acceptance (#21727).
Wrong message for SSH at boot time fixed (#21816).
Consistent time stamp formats in PDF Report Format (#21855).
Bugfix for file upload for NVT preferences (#22092).
Help text in CLI admin cleaned up (#22340).
1.7.0-21 (2012-05-03): Security update for various OpenSSL vulnerabilities (CVE-2012-0884, CVE-2012-1165, CVE-2012-2110, CVE-2012-2131).
1.7.0-20 (2012-04-19): Automation of feed updates of slave units that run GOS 2.0.
1.7.0-19 (2012-04-18): The CLI Admin now allows explicit deactivation of feed sync activity. When importing a Scan Config, no comment entries are lost anymore. Improved validation of hostnames for Targets. Preparation for using Slave units that run GOS 2.0 (creation of master keys). Improved SNMP service. Host summary in HTML exports extended with columns for scan start and scan end.
1.7.0-18 (2012-03-21): New option in gos-admin-menu to set the session timeout of the web interface. Various improvements of gos-admin-menu. Various small bug fixes and improvements of the web interface: Icons for VMWare products (for example ESXi), wrong minutes in schedules, improved host counting in Targets, limitation of column size for long host lists for Targets for better tabular overview, results details button for Observer role now works.
1.7.0-17 (2012-02-07): Bugfix for manually issued escalators regarding filters. Improved web interface: If NVT names are abbreviated, now a tooltip offers full name including OID. Extended gos-admin-menu.
1.7.0-16 (2012-01-26): Improved performance of SCAP data synchronisation. Bugfix for escalators that directly use a report plugin format. Extended gos-admin-menu.
1.7.0-15 (2012-01-23): Host details become as host scans complete, not only as whole network scan finishes. Bugfix for Feed connection in restricted environments. Bugfix for restoring Target objects from trashcan. Bugfix for GOS logging.
1.7.0-14 (2012-01-10): Bugfix for Chrome browser, bugfix for report format plugin removal, updated gos-admin-menu
1.7.0-13 (2011-12-22): Bugfix for timezone setting
1.7.0-12 (2011-12-12): First customer release of 1.7.0